Konfirmity

Part of the MAS TRM compliance guide

MAS Outsourcing Requirements: Material Arrangements, Audit Rights and Exit Plans

Amit Gupta

Amit Gupta

2026-10-05

MAS Outsourcing Requirements: Material Arrangements, Audit Rights and Exit Plans

MAS outsourcing requirements rest on one principle: outsourcing the function does not outsource the responsibility. A financial institution that hands a technology service to a provider remains accountable for the technology risk in that arrangement, and the Monetary Authority of Singapore supervises the institution on that basis — not the vendor.

That is why outsourcing risk at a financial institution in Singapore is governed as the institution's own risk. Where an arrangement is assessed as material, the expectations rise: documented assessment, due diligence, specific contract provisions, ongoing monitoring, and a worked exit plan. The practical failure is rarely a missing policy — it is a contract signed without the audit and inspection rights a material arrangement needs, discovered two years later when someone asks for them.

Why MAS Outsourcing Requirements Sit in Their Own Guidelines

MAS's outsourcing expectations live in a separate Guidelines on Outsourcing document, distinct from the Technology Risk Management Guidelines. Teams that treat the TRM Guidelines as the whole picture miss obligations, because the two do different jobs.

The TRM Guidelines, last revised in January 2021, set the technology-risk standard for the institution's own estate, and address third-party and vendor technology risk as one of their domains. The Guidelines on Outsourcing govern the arrangement itself — how you assess it, what the contract must secure, how you monitor it, how you get out of it. An arrangement can be fully compliant with your TRM control set and still be an unmanaged outsourcing arrangement in MAS's terms.

Both are guidelines rather than law, carrying no direct penalty in themselves — but MAS expects adherence, and the degree of observance feeds its supervisory risk assessment of the institution. If that distinction is new, the TRM Guidelines explained in plain terms is the place to start. Read both documents at the MAS website rather than a secondary summary — outsourcing coverage online is unusually stale.

What Makes an Outsourcing Arrangement Material

Materiality is the decision everything else hangs off. A material outsourcing arrangement is one whose failure or disruption would have a significant effect on the institution — its operations, its service to customers, its financial position, or its ability to meet regulatory obligations. MAS does not hand you a threshold table: the institution makes the assessment and documents it. Two institutions can outsource the same service and reach different answers, because the same provider is load-bearing for one and peripheral for the other.

So write it down. A 1-page record per arrangement naming what the provider does, which business services depend on it, what happens if it stops, what data it touches, and the materiality call with a named approver. The approver matters: materiality is a risk decision and should carry a signature from someone whose job includes owning that risk.

Then revisit it, because materiality drifts. An analytics tool bought for one team becomes the reporting path for a regulated process. A payments provider handling a tenth of volume handles most of it after a migration. An arrangement called non-material at signing and never reassessed is the commonest weak point in an otherwise reasonable register.

Want a second read on your outsourcing register?

Share your work email and we'll review how your material outsourcing assessments are documented, and which arrangements are missing audit rights or an exit plan.

We check that your email domain is real and can receive mail before sending. If we can't verify it, we won't be able to follow up — so please use a work address rather than a forwarding or temporary one.

We'd like to know who we're talking to. By submitting this form you agree that we may contact you about Konfirmity — no more than six emails a year, and we won't ask again each time. You can unsubscribe from any of them, and we'll stop. See our Privacy Policy.

What a Material Outsourcing Arrangement Needs Documented

A material outsourcing arrangement needs 5 documented artefacts, and an examiner will ask for them per arrangement rather than in aggregate.

ArtefactWhat it should contain
Materiality assessmentWhat the provider does, the business services dependent on it, the impact of failure or disruption, the data involved, the materiality call, the named approver and date, the review trigger.
Due diligence recordFinancial standing, ownership and governance, security and technical capability, independent assurance with its scope read rather than its logo noted, resilience and recovery, service and data locations, sub-contractors identified.
Contract provisionsScope and service levels, security and confidentiality obligations, audit and inspection rights for the institution, its auditors and MAS, incident notification and timing, sub-outsourcing consent and disclosure, data location and return, continuity commitments, exit assistance.
Monitoring recordNamed owner, review cadence, service-level performance against the contract, security and incident reporting received, changes to sub-contractors or locations, re-performed due diligence, findings raised.
Exit planTrigger conditions, who decides, the alternative provider or in-house path, data and configuration return in a usable format, realistic timeline, cost, dependencies that make exit hard, last review date.

Four of the five are living records. Only the contract is fixed in time, which is why it has to be right before you sign.

MAS Audit Rights Over a Vendor, and How to Secure Them

MAS audit rights over a vendor are the clause hardest to obtain after the fact. For material outsourcing arrangements, MAS's expectations include the ability to exercise inspection rights over the arrangement and the service provider — and that ability has to be created contractually, before signature, because the regulator's authority runs to your institution and your contract is what extends reach to the vendor.

A standard vendor paper will not contain it. Most providers offer instead a "right to receive our SOC 2 report on request", which is neither an audit right nor an inspection right. Negotiate for the specifics:

  • Named beneficiaries. The institution, its internal and external auditors, and MAS or any person appointed by MAS. Naming the regulator is the part vendors most often strike and the part you most need.
  • Scope that reaches the service. Records, systems, controls, personnel and premises used to deliver the service — not just corporate policy documents.
  • Reasonable notice, with an exception. A notice period is fair; an unqualified one is not, because a regulator-driven inspection may not accommodate it. Carve out regulatory requests.
  • Who pays, and the frequency. Settle it in the contract; left open, it becomes a negotiation at the worst moment.
  • Flow-down to sub-contractors. Rights that stop at your direct provider stop short of where the service runs.
  • Assurance as a complement, not a substitute. Contract for independent reports too, but reject any clause offering them "in lieu of" audit access.
  • Survival past termination. Record access for a defined period after the arrangement ends, so an inspection of the final year is still possible.

Get these at term sheet stage. Once commercial terms are agreed and legal is closing, the provider has no reason to reopen them, and renewal is your next realistic chance.

Due Diligence Before Engagement, Monitoring After

Due diligence before engagement is the part most programmes do competently. Monitoring after engagement is where they decay, and the decay is quiet.

Pre-engagement, establish that the provider can deliver the service to the standard your obligations require: financial viability, security capability, resilience, where the service is delivered from, where data sits, and what independent assurance exists. Read the scope section of any certificate rather than the cover — one whose scope excludes the product you are buying tells you nothing about it. Our walkthrough of vendor due diligence for MAS-regulated buyers covers the questionnaire side.

Post-engagement is a standing obligation, not an annual form. The institution should know continuously whether service levels are met, what incidents the provider reported, whether its sub-contractors or delivery locations changed, and whether the materiality call still holds. Assign 1 named owner per material arrangement inside the business — not procurement, not a shared mailbox — and keep the monitoring record with the assessment.

Sub-Outsourcing and the Fourth Parties Behind Your Provider

Sub-outsourcing is the chain beyond your direct provider, and it is where visibility usually ends. Your provider's fourth parties — their hosting, their subprocessors, their offshore delivery centres — can carry the same risk to your institution as the provider itself while sitting outside your contract.

Handle it in 2 places. In the contract: require disclosure of material sub-contractors, require consent or at minimum advance notification before a change, and flow down the security, confidentiality and audit obligations. In the monitoring record: keep the sub-contractor list current and check it, because a provider that changes hosting region or adds an offshore support team has changed your arrangement whether or not they told you.

The hardest case is a provider whose own critical dependency is a hyperscaler. You will not be auditing that hyperscaler, and MAS treats cloud within this framework rather than under a cloud-only rulebook — see how MAS treats cloud arrangements. What you can do is establish that your provider governs the dependency and its own exit position is not theoretical.

Concentration Risk and Exit Planning

Concentration risk and exit planning are the same problem seen from two angles: an arrangement you cannot exit is a risk you cannot treat.

Concentration shows up in 3 shapes. One provider across several material services, so a single failure is a multi-service failure. One provider used by enough institutions that an outage is a sector event rather than your event. And one provider so embedded in your operating model that migration is not realistically achievable — the most dangerous, because it looks like stability.

Exit planning is the control. A usable plan names the triggers, the decision-maker, the alternative path, how data and configuration come back in a format you can load, the honest timeline and the cost. The honesty is the hard part: a plan claiming a 3-month migration for a core platform that took 18 months to implement is a document, not a plan. Pressure-test it — proprietary formats with no documented export, exit assistance that exists only as goodwill, a skills gap left by years of outsourcing the capability. Each is a finding you can act on now and cannot act on during an exit.

Selling Into a MAS-Regulated Buyer as a Vendor

If you are a vendor selling into MAS-regulated buyers, these obligations reach you as contract demands and questionnaire items whether or not you are regulated yourself. The institution cannot transfer its accountability to you, so it transfers the evidence burden instead.

Expect 4 recurring asks. Audit and inspection rights naming MAS and the institution's auditors, which your standard paper almost certainly does not grant. Disclosure of your subprocessors and delivery locations, with notification before you change them. Incident notification on a tight clock, because the institution has its own regulatory duty behind yours. And exit assistance with data return in a usable format.

These are deal-speed levers. A vendor whose master agreement already contains a regulator-inclusive audit clause, whose subprocessor list is published and current, and whose incident notification commitment is written rather than negotiated, clears third-party risk review in weeks instead of quarters. A vendor that fights the audit clause signals it has not been through this before.

Build the pack once: an assurance report whose scope genuinely covers the service you sell, a current subprocessor list, resilience test results, and a pre-cleared contract position on audit, incidents, sub-outsourcing and exit. The same artefacts answer equivalent demands elsewhere, which is why the discipline behind ISO 27001 third-party risk and SOC 2 third-party risk transfers to MAS buyers.

MAS Outsourcing Questions Risk Teams Ask

These are the 5 MAS outsourcing questions risk teams ask most often once they start building an arrangement-by-arrangement register.

No. They are separate documents with overlapping subject matter. The TRM Guidelines set technology-risk expectations across the institution's estate, including third-party and vendor technology risk. The Guidelines on Outsourcing govern the arrangement itself — materiality, due diligence, contract provisions, monitoring and exit. Teams reading only the TRM Guidelines usually have reasonable controls and no defensible register.

The institution does, and it documents the assessment. MAS publishes no threshold table, so there is no figure to compare against. The assessment turns on the effect failure or disruption would have on the institution's operations, its service to customers, its financial position and its ability to meet regulatory obligations. What matters at examination is that it exists, is reasoned, is approved by someone who owns the risk, and is revisited as the arrangement changes.

Treat it as a risk decision rather than a legal one, and take it before signing. The realistic options: negotiate harder while commercial leverage exists, accept narrower rights with a documented compensating position such as contracted assurance plus enhanced monitoring, restructure so the vendor is not material, or choose another provider. What is not an option is recording the gap nowhere — reduced rights need an owner, a rationale and a review date.

Yes. MAS treats cloud within the outsourcing and technology-risk framework rather than under a cloud-only rulebook, so a material cloud arrangement attracts the same expectations. The practical differences: audit rights are usually satisfied through contracted assurance reports and pooled audit mechanisms rather than site visits, and exit analysis needs more work because the dependency is deeper.

Monitoring is continuous; formal review should be event-driven as well as periodic. Re-perform due diligence on a cadence set by materiality, and additionally on contract renewal, on any material change in scope, volume or delivery location, on any change to sub-contractors, and after any significant provider incident. An arrangement never revisited since signature is the pattern that surfaces most often at examination.

Keep every material outsourcing arrangement examination-ready

Book a demo and we'll show how Konfirmity holds the materiality assessment, due diligence, contract position, monitoring record and exit plan for each arrangement in one place.

Book a demo

Treat the Materiality Assessment as the Load-Bearing Decision

Start with the register, and start with materiality. Until each arrangement has a documented, approved materiality call, you cannot tell which contracts needed audit rights, which need exit plans, or where concentration actually sits.

Then work the contracts in materiality order. Audit and inspection rights, sub-outsourcing disclosure, the incident notification clock and exit assistance are cheap before signature and expensive afterwards, so arrangements renewing in the next 2 quarters are where attention pays best.

The uncomfortable arrangements — the embedded provider you could not realistically replace, the one whose sub-contractors you cannot name — are findings rather than failures. Record them, assign them, give them a review date. For the wider control set they sit inside, the MAS TRM compliance checklist gives you the sequence to work through next.

Tools

Put your MAS TRM plan into numbers

More MAS TRM guides

Related Articles

MAS and Cloud Computing: How the TRM and Outsourcing Expectations Apply

Cloud & DevOps

amit-gupta

2026-10-05

MAS and Cloud Computing: How the TRM and Outsourcing Expectations Apply

arrow

MAS cloud computing requirements sit in the TRM and Outsourcing Guidelines, not a cloud rulebook. What that means for audit rights and shared responsibility.

MAS TRM Compliance Checklist: A Phased Readiness Plan for FIs

Templates & Checklists

amit-gupta

2026-10-05

MAS TRM Compliance Checklist: A Phased Readiness Plan for FIs

arrow

A phased MAS TRM compliance checklist for Singapore FIs: what applies to you, governance, cyber hygiene, outsourcing, and who owns each output.

MAS TRM Guidelines Explained: What MAS Expects and What You Must Show

Beginner Guides

amit-gupta

2026-10-05

MAS TRM Guidelines Explained: What MAS Expects and What You Must Show

arrow

The MAS TRM Guidelines are guidance; a MAS Notice is law. What that means for a regulated financial institution, and the domains the Guidelines cover.

MAS Incident Notification: Operating the One-Hour Clock

Risk & Incidents

amit-gupta

2026-10-05

MAS Incident Notification: Operating the One-Hour Clock

arrow

MAS incident notification runs on a 1 hour clock from discovery, with a root cause report at 14 days. How to decide, who notifies, and why Notice 644 is gone.

MAS Notice 655: The Six Cyber Hygiene Measures and What Evidences Them

Security Controls & Practices

amit-gupta

2026-10-05

MAS Notice 655: The Six Cyber Hygiene Measures and What Evidences Them

arrow

MAS Notice 655, now also FSM-N06, is binding law, not guidance. Walk all six cyber hygiene measures, what each demands, and the evidence that proves it.

MAS Vendor Due Diligence: What Singapore FIs Ask You, and Why

Leadership & Strategy

amit-gupta

2026-10-05

MAS Vendor Due Diligence: What Singapore FIs Ask You, and Why

arrow

MAS vendor due diligence from the vendor's side: why the questionnaire runs so deep, which clauses never move in redlines, and what to prepare before it lands.

How Real Security Becomes Compliance

Built by the CTO who scaled NIUM to $2 billion. 10 years building security and compliance for regulated fintechs. 4.5 years running Konfirmity profitably.

Book a call